File name:

SQLi Dumper v8.5 [VeryClean] Stephanny.rar

Full analysis: https://app.any.run/tasks/61f824b1-47bf-457f-b700-b7875bd87520
Verdict: Malicious activity
Analysis date: March 11, 2024, 00:03:57
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

FD8391F48EBA68B70023C7C45F78A1F2

SHA1:

7F65D9871014E028873B29AA8F715B111F0B5568

SHA256:

3EE7B87B2531F264DFD877B42DEFF1026C4C332AEB30E9BDB2C600643956CE5A

SSDEEP:

98304:w3c6n8TWWOjAt+IXJTjT0OfzEwtxL5htKcZgNcNb39tEevL31GsjU6eVpU:SbaL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 2472)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 2472)
      • SQLi v.8.5 VeryClean by Stephanny.exe (PID: 2044)
    • Reads settings of System Certificates

      • SQLi v.8.5 VeryClean by Stephanny.exe (PID: 2044)
    • Reads the Internet Settings

      • SQLi v.8.5 VeryClean by Stephanny.exe (PID: 2044)
    • Requests information from PasteBin

      • SQLi v.8.5 VeryClean by Stephanny.exe (PID: 2044)
    • Reads Microsoft Outlook installation path

      • SQLi v.8.5 VeryClean by Stephanny.exe (PID: 2044)
    • Reads Internet Explorer settings

      • SQLi v.8.5 VeryClean by Stephanny.exe (PID: 2044)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2472)
    • Checks supported languages

      • SQLi v.8.5 VeryClean by Stephanny.exe (PID: 2044)
    • Reads the computer name

      • SQLi v.8.5 VeryClean by Stephanny.exe (PID: 2044)
    • Reads Environment values

      • SQLi v.8.5 VeryClean by Stephanny.exe (PID: 2044)
    • Reads the machine GUID from the registry

      • SQLi v.8.5 VeryClean by Stephanny.exe (PID: 2044)
    • Checks proxy server information

      • SQLi v.8.5 VeryClean by Stephanny.exe (PID: 2044)
    • Reads the software policy settings

      • SQLi v.8.5 VeryClean by Stephanny.exe (PID: 2044)
    • Create files in a temporary directory

      • SQLi v.8.5 VeryClean by Stephanny.exe (PID: 2044)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe sqli v.8.5 veryclean by stephanny.exe

Process information

PID
CMD
Path
Indicators
Parent process
2044"C:\Users\admin\AppData\Local\Temp\Rar$EXa2472.44866\SQLi Dumper v8.5 [VeryClean]\SQLi v.8.5 VeryClean by Stephanny.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXa2472.44866\SQLi Dumper v8.5 [VeryClean]\SQLi v.8.5 VeryClean by Stephanny.exe
WinRAR.exe
User:
admin
Company:
SQLi Trush Corp
Integrity Level:
MEDIUM
Description:
SQLi Dumper v8.0
Exit code:
0
Version:
8.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\rar$exa2472.44866\sqli dumper v8.5 [veryclean]\sqli v.8.5 veryclean by stephanny.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2472"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\SQLi Dumper v8.5 [VeryClean] Stephanny.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
11 246
Read events
11 190
Write events
56
Delete events
0

Modification events

(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2472) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\SQLi Dumper v8.5 [VeryClean] Stephanny.rar
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2472) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
1
Suspicious files
4
Text files
4
Unknown types
1

Dropped files

PID
Process
Filename
Type
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2472.44866\SQLi Dumper v8.5 [VeryClean]\Settingsxml
MD5:6CADCD28429156CBC1D77447BBDDDF42
SHA256:88AD0488FE62D131F1CA29A7DE9470038E436F33F76CE1A83D6B41BDF3DC6C7C
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2472.44866\SQLi Dumper v8.5 [VeryClean]\DIC\dic_admin.txttext
MD5:F4675FA366AAE47396F8CFB2F3EB1B9A
SHA256:826FBBAA5DE45C1238FC7B9F4436C1B87444F8103F4F65180F8547E3F271A413
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2472.44866\SQLi Dumper v8.5 [VeryClean]\SQLi v.8.5 VeryClean by Stephanny.exeexecutable
MD5:439D7B9E06665AA69EA8E0D0F2BCA1C4
SHA256:CE8D265248017A1CA412374FAF246AAABB7E963CA7787C9FCA94CA8074852FB8
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2472.44866\SQLi Dumper v8.5 [VeryClean]\Settings.xmlxml
MD5:4B865662766469CC99CA0BEA1EF02ABC
SHA256:9AF99A46F699E0F9E3A9663ACE9B15C7F70377E4A4E18FBABA92E9DCC4A8FCA7
2044SQLi v.8.5 VeryClean by Stephanny.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:C04C1D90B321701AF50F547B9A4E5480
SHA256:117FD5C1D837EA5E357244ABD0C8465650676719AEA351D8C12887D505FA50E1
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2472.44866\SQLi Dumper v8.5 [VeryClean]\GeoIP.datbinary
MD5:CB9AD69965F9F4CFF8572983F60BE67C
SHA256:56C7079DC309168D9C41DD4A7A61033ACD264A120CA8D2E2182ABB5B9AE6B0A3
2472WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXa2472.44866\SQLi Dumper v8.5 [VeryClean]\DIC\dic_file_dump.txttext
MD5:351CACFFC2884FCD4E69BB1FB04DDEB5
SHA256:C67BCC0B4ED5E5EF72AA1134C0838D9201A97C2BF462FDFF0AC9052A53B286A2
2044SQLi v.8.5 VeryClean by Stephanny.exeC:\Users\admin\AppData\Local\Temp\Tar46BF.tmpbinary
MD5:DD73CEAD4B93366CF3465C8CD32E2796
SHA256:A6752B7851B591550E4625B832A393AABCC428DE18D83E8593CD540F7D7CAE22
2044SQLi v.8.5 VeryClean by Stephanny.exeC:\Users\admin\AppData\Local\Temp\Cab46BE.tmpcompressed
MD5:753DF6889FD7410A2E9FE333DA83A429
SHA256:B42DC237E44CBC9A43400E7D3F9CBD406DBDEFD62BFE87328F8663897D69DF78
2044SQLi v.8.5 VeryClean by Stephanny.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:753DF6889FD7410A2E9FE333DA83A429
SHA256:B42DC237E44CBC9A43400E7D3F9CBD406DBDEFD62BFE87328F8663897D69DF78
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
192
TCP/UDP connections
218
DNS requests
13
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2044
SQLi v.8.5 VeryClean by Stephanny.exe
GET
301
172.67.34.170:80
http://pastebin.com/raw/3vsJLpWu
unknown
unknown
2044
SQLi v.8.5 VeryClean by Stephanny.exe
GET
302
172.64.151.32:80
http://www.webcrawler.com/search/web?q=YouTube+%3a+https%3a%2f%2fwww.youtube.com%2fxRiskyx
unknown
unknown
2044
SQLi v.8.5 VeryClean by Stephanny.exe
GET
301
151.101.66.114:80
http://www.ask.com/web?q=YouTube+%3a+https%3a%2f%2fwww.youtube.com%2fxRiskyx
unknown
unknown
2044
SQLi v.8.5 VeryClean by Stephanny.exe
GET
301
151.101.2.114:80
http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?searchfor=YouTube+%3a+https%3a%2f%2fwww.youtube.com%2fxRiskyx
unknown
unknown
2044
SQLi v.8.5 VeryClean by Stephanny.exe
GET
93.186.134.233:80
http://www.bing.com/search?q=YouTube+%3a+https%3a%2f%2fwww.youtube.com%2fxRiskyx&count=50
unknown
unknown
2044
SQLi v.8.5 VeryClean by Stephanny.exe
GET
301
212.82.100.137:80
http://www.wow.com/search?q=YouTube+%3a+https%3a%2f%2fwww.youtube.com%2fxRiskyx
unknown
text
25 b
unknown
2044
SQLi v.8.5 VeryClean by Stephanny.exe
GET
301
212.82.100.137:80
http://search.yahoo.com/search?n=100&p=YouTube+%3a+https%3a%2f%2fwww.youtube.com%2fxRiskyx
unknown
text
25 b
unknown
2044
SQLi v.8.5 VeryClean by Stephanny.exe
GET
301
212.82.100.137:80
http://search.aol.com/aol/search?&q=YouTube+%3a+https%3a%2f%2fwww.youtube.com%2fxRiskyx
unknown
text
25 b
unknown
2044
SQLi v.8.5 VeryClean by Stephanny.exe
GET
200
5.255.255.80:80
http://www.yandex.com/yandsearch?text=YouTube+%3a+https%3a%2f%2fwww.youtube.com%2fxRiskyx
unknown
html
61.6 Kb
unknown
2044
SQLi v.8.5 VeryClean by Stephanny.exe
GET
301
151.101.2.114:80
http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?searchfor=YouTube+%3a+https%3a%2f%2fwww.youtube.com%2fxRiskyx
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2044
SQLi v.8.5 VeryClean by Stephanny.exe
172.67.34.170:80
pastebin.com
CLOUDFLARENET
US
unknown
2044
SQLi v.8.5 VeryClean by Stephanny.exe
172.67.34.170:443
pastebin.com
CLOUDFLARENET
US
unknown
2044
SQLi v.8.5 VeryClean by Stephanny.exe
142.250.186.36:443
www.google.com
GOOGLE
US
whitelisted
2044
SQLi v.8.5 VeryClean by Stephanny.exe
5.255.255.80:80
www.yandex.com
YANDEX LLC
RU
whitelisted
2044
SQLi v.8.5 VeryClean by Stephanny.exe
212.82.100.137:80
search.yahoo.com
Yahoo! UK Services Limited
IE
shared
2044
SQLi v.8.5 VeryClean by Stephanny.exe
93.186.134.233:80
www.bing.com
TELECOM ITALIA SPARKLE S.p.A.
IT
unknown

DNS requests

Domain
IP
Reputation
pastebin.com
  • 172.67.34.170
  • 104.20.67.143
  • 104.20.68.143
shared
www.webcrawler.com
  • 172.64.151.32
  • 104.18.36.224
whitelisted
www.bing.com
  • 93.186.134.233
  • 93.186.134.243
whitelisted
search.yahoo.com
  • 212.82.100.137
whitelisted
www.yandex.com
  • 5.255.255.80
  • 77.88.55.77
  • 5.255.255.88
  • 77.88.55.80
whitelisted
search.mywebsearch.com
  • 151.101.2.114
  • 151.101.194.114
  • 151.101.130.114
  • 151.101.66.114
whitelisted
search.aol.com
  • 212.82.100.137
whitelisted
pesquisa.sapo.pt
  • 213.13.145.10
unknown
www.google.com
  • 142.250.186.36
whitelisted
www.wow.com
  • 212.82.100.137
whitelisted

Threats

Found threats are available for the paid subscriptions
1 ETPRO signatures available at the full report
No debug info